Doing the first scan closed the program and restarted the computer so I did the scan again and copied all this before the computer rebooted itself.
GMER 1.0.13.12551 -
http://www.gmer.net
Rootkit scan 2007-09-05 09:23:25
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.13 ----
SSDT \??\C:\WINDOWS\system32\xpdx.sys ZwCreateKey
SSDT \??\C:\WINDOWS\system32\xpdx.sys ZwOpenKey
SSDT \??\C:\WINDOWS\system32\xpdx.sys ZwTerminateProcess
---- Kernel code sections - GMER 1.0.13 ----
? C:\WINDOWS\system32\xpdx.sys The system cannot find the file specified.
.text ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA2849
.text ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA2896
---- User code sections - GMER 1.0.13 ----
.text C:\WINDOWS\System32\wbem\wmiprvse.exe[492] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA2849
.text C:\WINDOWS\System32\wbem\wmiprvse.exe[492] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA289D
.text C:\WINDOWS\System32\wbem\wmiprvse.exe[492] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA28AA
.text C:\WINDOWS\System32\wbem\wmiprvse.exe[492] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA2896
.text C:\WINDOWS\explorer.exe[548] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA2849
.text C:\WINDOWS\explorer.exe[548] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA289D
.text C:\WINDOWS\explorer.exe[548] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA28AA
.text C:\WINDOWS\explorer.exe[548] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA2896
.text C:\WINDOWS\system32\winlogon.exe[800] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA2849
.text C:\WINDOWS\system32\winlogon.exe[800] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA289D
.text C:\WINDOWS\system32\winlogon.exe[800] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA28AA
.text C:\WINDOWS\system32\winlogon.exe[800] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA2896
.text C:\WINDOWS\system32\services.exe[844] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA2849
.text C:\WINDOWS\system32\services.exe[844] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA289D
.text C:\WINDOWS\system32\services.exe[844] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA28AA
.text C:\WINDOWS\system32\services.exe[844] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA2896
.text C:\WINDOWS\system32\lsass.exe[856] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FF92849
.text C:\WINDOWS\system32\lsass.exe[856] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FF9289D
.text C:\WINDOWS\system32\lsass.exe[856] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FF928AA
.text C:\WINDOWS\system32\lsass.exe[856] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FF92896
.text C:\WINDOWS\system32\svchost.exe[1008] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA2849
.text C:\WINDOWS\system32\svchost.exe[1008] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA289D
.text C:\WINDOWS\system32\svchost.exe[1008] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA28AA
.text C:\WINDOWS\system32\svchost.exe[1008] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA2896
.text C:\WINDOWS\system32\svchost.exe[1124] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA2849
.text C:\WINDOWS\system32\svchost.exe[1124] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA289D
.text C:\WINDOWS\system32\svchost.exe[1124] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA28AA
.text C:\WINDOWS\system32\svchost.exe[1124] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA2896
.text C:\WINDOWS\system32\svchost.exe[1384] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA2849
.text C:\WINDOWS\system32\svchost.exe[1384] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA289D
.text C:\WINDOWS\system32\svchost.exe[1384] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA28AA
.text C:\WINDOWS\system32\svchost.exe[1384] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA2896
.text C:\WINDOWS\System32\svchost.exe[1420] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA2849
.text C:\WINDOWS\System32\svchost.exe[1420] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA289D
.text C:\WINDOWS\System32\svchost.exe[1420] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA28AA
.text C:\WINDOWS\System32\svchost.exe[1420] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA2896
.text C:\WINDOWS\System32\svchost.exe[1484] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA2849
.text C:\WINDOWS\System32\svchost.exe[1484] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA289D
.text C:\WINDOWS\System32\svchost.exe[1484] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA28AA
.text C:\WINDOWS\System32\svchost.exe[1484] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA2896
.text C:\WINDOWS\System32\svchost.exe[1616] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA2849
.text C:\WINDOWS\System32\svchost.exe[1616] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA289D
.text C:\WINDOWS\System32\svchost.exe[1616] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA28AA
.text C:\WINDOWS\System32\svchost.exe[1616] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA2896
.text C:\My Downloads\gmer.exe[1816] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA2849
.text C:\My Downloads\gmer.exe[1816] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA2896
.text C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe[1940] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA2849
.text C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe[1940] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA289D
.text C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe[1940] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA28AA
.text C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe[1940] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA2896
.text C:\My Downloads\gmer.exe[1952] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA2849
.text C:\My Downloads\gmer.exe[1952] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA2896
---- User IAT/EAT - GMER 1.0.13 ----
IAT C:\WINDOWS\System32\wbem\wmiprvse.exe[492] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00404203
IAT C:\WINDOWS\System32\wbem\wmiprvse.exe[492] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 004041C5
IAT C:\WINDOWS\System32\wbem\wmiprvse.exe[492] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 00404192
IAT C:\WINDOWS\System32\wbem\wmiprvse.exe[492] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 0040B490
IAT C:\WINDOWS\System32\wbem\wmiprvse.exe[492] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetMessageW] 0040B777
IAT C:\WINDOWS\System32\wbem\wmiprvse.exe[492] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!PeekMessageW] 0040B7D2
IAT C:\WINDOWS\System32\wbem\wmiprvse.exe[492] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!PeekMessageW] 0040B7D2
IAT C:\WINDOWS\System32\wbem\wmiprvse.exe[492] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetMessageW] 0040B777
IAT C:\WINDOWS\System32\wbem\wmiprvse.exe[492] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 0040B490
IAT C:\WINDOWS\System32\wbem\wmiprvse.exe[492] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetMessageA] 0040B74B
IAT C:\WINDOWS\System32\wbem\wmiprvse.exe[492] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetMessageW] 0040B777
IAT C:\WINDOWS\System32\wbem\wmiprvse.exe[492] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!PeekMessageA] 0040B7A3
IAT C:\WINDOWS\System32\wbem\wmiprvse.exe[492] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!PeekMessageW] 0040B7D2
IAT C:\WINDOWS\system32\services.exe[844] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00054203
IAT C:\WINDOWS\system32\services.exe[844] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 000541C5
IAT C:\WINDOWS\system32\services.exe[844] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 00054192
IAT C:\WINDOWS\system32\services.exe[844] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 0005B490
IAT C:\WINDOWS\system32\services.exe[844] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetMessageW] 0005B777
IAT C:\WINDOWS\system32\services.exe[844] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!PeekMessageW] 0005B7D2
IAT C:\WINDOWS\system32\services.exe[844] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!PeekMessageW] 0005B7D2
IAT C:\WINDOWS\system32\services.exe[844] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetMessageW] 0005B777
IAT C:\WINDOWS\system32\services.exe[844] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 0005B490
IAT C:\WINDOWS\system32\services.exe[844] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetMessageA] 0005B74B
IAT C:\WINDOWS\system32\services.exe[844] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetMessageW] 0005B777
IAT C:\WINDOWS\system32\services.exe[844] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!PeekMessageA] 0005B7A3
IAT C:\WINDOWS\system32\services.exe[844] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!PeekMessageW] 0005B7D2
IAT C:\WINDOWS\system32\lsass.exe[856] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00B74203
IAT C:\WINDOWS\system32\lsass.exe[856] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00B741C5
IAT C:\WINDOWS\system32\lsass.exe[856] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 00B74192
IAT C:\WINDOWS\system32\lsass.exe[856] @ C:\WINDOWS\system32\LSASRV.dll [ntdll.dll!LdrLoadDll] 00B74203
IAT C:\WINDOWS\system32\lsass.exe[856] @ C:\WINDOWS\system32\SAMSRV.dll [ntdll.dll!LdrLoadDll] 00B74203
IAT C:\WINDOWS\system32\lsass.exe[856] @ C:\WINDOWS\system32\SAMSRV.dll [ntdll.dll!LdrGetProcedureAddress] 00B741C5
IAT C:\WINDOWS\system32\lsass.exe[856] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00B7B490
IAT C:\WINDOWS\system32\lsass.exe[856] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetMessageW] 00B7B777
IAT C:\WINDOWS\system32\lsass.exe[856] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!PeekMessageW] 00B7B7D2
IAT C:\WINDOWS\system32\lsass.exe[856] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!PeekMessageW] 00B7B7D2
IAT C:\WINDOWS\system32\lsass.exe[856] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetMessageW] 00B7B777
IAT C:\WINDOWS\system32\lsass.exe[856] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00B7B490
IAT C:\WINDOWS\system32\lsass.exe[856] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetMessageA] 00B7B74B
IAT C:\WINDOWS\system32\lsass.exe[856] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetMessageW] 00B7B777
IAT C:\WINDOWS\system32\lsass.exe[856] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!PeekMessageA] 00B7B7A3
IAT C:\WINDOWS\system32\lsass.exe[856] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!PeekMessageW] 00B7B7D2
IAT C:\WINDOWS\system32\svchost.exe[1008] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 00C14192
IAT C:\WINDOWS\system32\svchost.exe[1124] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00894203
IAT C:\WINDOWS\system32\svchost.exe[1124] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 008941C5
IAT C:\WINDOWS\system32\svchost.exe[1124] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 00894192
IAT C:\WINDOWS\system32\svchost.exe[1124] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 0089B490
IAT C:\WINDOWS\system32\svchost.exe[1124] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetMessageW] 0089B777
IAT C:\WINDOWS\system32\svchost.exe[1124] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!PeekMessageW] 0089B7D2
IAT C:\WINDOWS\system32\svchost.exe[1124] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!PeekMessageW] 0089B7D2
IAT C:\WINDOWS\system32\svchost.exe[1124] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetMessageW] 0089B777
IAT C:\WINDOWS\system32\svchost.exe[1124] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 0089B490
IAT C:\WINDOWS\system32\svchost.exe[1124] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetMessageA] 0089B74B
IAT C:\WINDOWS\system32\svchost.exe[1124] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetMessageW] 0089B777
IAT C:\WINDOWS\system32\svchost.exe[1124] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!PeekMessageA] 0089B7A3
IAT C:\WINDOWS\system32\svchost.exe[1124] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!PeekMessageW] 0089B7D2
IAT C:\WINDOWS\system32\svchost.exe[1384] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 01034203
IAT C:\WINDOWS\system32\svchost.exe[1384] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 010341C5
IAT C:\WINDOWS\system32\svchost.exe[1384] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 01034192
IAT C:\WINDOWS\system32\svchost.exe[1384] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 0103B490
IAT C:\WINDOWS\system32\svchost.exe[1384] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetMessageW] 0103B777
IAT C:\WINDOWS\system32\svchost.exe[1384] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!PeekMessageW] 0103B7D2
IAT C:\WINDOWS\system32\svchost.exe[1384] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!PeekMessageW] 0103B7D2
IAT C:\WINDOWS\system32\svchost.exe[1384] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetMessageW] 0103B777
IAT C:\WINDOWS\system32\svchost.exe[1384] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 0103B490
IAT C:\WINDOWS\system32\svchost.exe[1384] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetMessageA] 0103B74B
IAT C:\WINDOWS\system32\svchost.exe[1384] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetMessageW] 0103B777
IAT C:\WINDOWS\system32\svchost.exe[1384] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!PeekMessageA] 0103B7A3
IAT C:\WINDOWS\system32\svchost.exe[1384] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!PeekMessageW] 0103B7D2
IAT C:\WINDOWS\System32\svchost.exe[1420] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 01A34203
IAT C:\WINDOWS\System32\svchost.exe[1420] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 01A341C5
IAT C:\WINDOWS\System32\svchost.exe[1420] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 01A34192
IAT C:\WINDOWS\System32\svchost.exe[1420] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 01A3B490
IAT C:\WINDOWS\System32\svchost.exe[1420] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetMessageW] 01A3B777
IAT C:\WINDOWS\System32\svchost.exe[1420] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!PeekMessageW] 01A3B7D2
IAT C:\WINDOWS\System32\svchost.exe[1420] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!PeekMessageW] 01A3B7D2
IAT C:\WINDOWS\System32\svchost.exe[1420] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetMessageW] 01A3B777
IAT C:\WINDOWS\System32\svchost.exe[1420] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 01A3B490
IAT C:\WINDOWS\System32\svchost.exe[1420] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetMessageA] 01A3B74B
IAT C:\WINDOWS\System32\svchost.exe[1420] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetMessageW] 01A3B777
IAT C:\WINDOWS\System32\svchost.exe[1420] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!PeekMessageA] 01A3B7A3
IAT C:\WINDOWS\System32\svchost.exe[1420] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!PeekMessageW] 01A3B7D2
IAT C:\WINDOWS\System32\svchost.exe[1484] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00884203
IAT C:\WINDOWS\System32\svchost.exe[1484] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 008841C5
IAT C:\WINDOWS\System32\svchost.exe[1484] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 00884192
IAT C:\WINDOWS\System32\svchost.exe[1484] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 0088B490
IAT C:\WINDOWS\System32\svchost.exe[1484] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetMessageW] 0088B777
IAT C:\WINDOWS\System32\svchost.exe[1484] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!PeekMessageW] 0088B7D2
IAT C:\WINDOWS\System32\svchost.exe[1484] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!PeekMessageW] 0088B7D2
IAT C:\WINDOWS\System32\svchost.exe[1484] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetMessageW] 0088B777
IAT C:\WINDOWS\System32\svchost.exe[1484] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 0088B490
IAT C:\WINDOWS\System32\svchost.exe[1484] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetMessageA] 0088B74B
IAT C:\WINDOWS\System32\svchost.exe[1484] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetMessageW] 0088B777
IAT C:\WINDOWS\System32\svchost.exe[1484] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!PeekMessageA] 0088B7A3
IAT C:\WINDOWS\System32\svchost.exe[1484] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!PeekMessageW] 0088B7D2
IAT C:\WINDOWS\System32\svchost.exe[1616] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 006B4203
IAT C:\WINDOWS\System32\svchost.exe[1616] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 006B41C5
IAT C:\WINDOWS\System32\svchost.exe[1616] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 006B4192
IAT C:\WINDOWS\System32\svchost.exe[1616] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 006BB490
IAT C:\WINDOWS\System32\svchost.exe[1616] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetMessageW] 006BB777
IAT C:\WINDOWS\System32\svchost.exe[1616] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!PeekMessageW] 006BB7D2
IAT C:\WINDOWS\System32\svchost.exe[1616] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!PeekMessageW] 006BB7D2
IAT C:\WINDOWS\System32\svchost.exe[1616] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetMessageW] 006BB777
IAT C:\WINDOWS\System32\svchost.exe[1616] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 006BB490
IAT C:\WINDOWS\System32\svchost.exe[1616] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetMessageA] 006BB74B
IAT C:\WINDOWS\System32\svchost.exe[1616] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetMessageW] 006BB777
IAT C:\WINDOWS\System32\svchost.exe[1616] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!PeekMessageA] 006BB7A3
IAT C:\WINDOWS\System32\svchost.exe[1616] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!PeekMessageW] 006BB7D2
IAT C:\My Downloads\gmer.exe[1816] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00134203
IAT C:\My Downloads\gmer.exe[1816] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 001341C5
IAT C:\My Downloads\gmer.exe[1816] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 00134192
IAT C:\My Downloads\gmer.exe[1816] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 0013B490
IAT C:\My Downloads\gmer.exe[1816] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetMessageW] 0013B777
IAT C:\My Downloads\gmer.exe[1816] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!PeekMessageW] 0013B7D2
IAT C:\My Downloads\gmer.exe[1816] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!PeekMessageW] 0013B7D2
IAT C:\My Downloads\gmer.exe[1816] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!GetMessageW] 0013B777
IAT C:\My Downloads\gmer.exe[1816] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!GetClipboardData] 0013B490
IAT C:\My Downloads\gmer.exe[1816] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetMessageA] 0013B74B
IAT C:\My Downloads\gmer.exe[1816] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetMessageW] 0013B777
IAT C:\My Downloads\gmer.exe[1816] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!PeekMessageA] 0013B7A3
IAT C:\My Downloads\gmer.exe[1816] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!PeekMessageW] 0013B7D2
IAT C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe[1940] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00BD4203
IAT C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe[1940] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00BD41C5
IAT C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe[1940] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 00BD4192
IAT C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe[1940] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!PeekMessageW] 00BDB7D2
IAT C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe[1940] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetMessageW] 00BDB777
IAT C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe[1940] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00BDB490
IAT C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe[1940] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetMessageA] 00BDB74B
IAT C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe[1940] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetMessageW] 00BDB777
IAT C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe[1940] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!PeekMessageA] 00BDB7A3
IAT C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe[1940] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!PeekMessageW] 00BDB7D2
IAT C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe[1940] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00BDB490
IAT C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe[1940] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetMessageW] 00BDB777
IAT C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe[1940] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!PeekMessageW] 00BDB7D2
IAT C:\My Downloads\gmer.exe[1952] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00134203
IAT C:\My Downloads\gmer.exe[1952] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 001341C5
IAT C:\My Downloads\gmer.exe[1952] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 00134192
IAT C:\My Downloads\gmer.exe[1952] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 0013B490
IAT C:\My Downloads\gmer.exe[1952] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetMessageW] 0013B777
IAT C:\My Downloads\gmer.exe[1952] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!PeekMessageW] 0013B7D2
IAT C:\My Downloads\gmer.exe[1952] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!PeekMessageW] 0013B7D2
IAT C:\My Downloads\gmer.exe[1952] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!GetMessageW] 0013B777
IAT C:\My Downloads\gmer.exe[1952] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!GetClipboardData] 0013B490
IAT C:\My Downloads\gmer.exe[1952] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetMessageA] 0013B74B
IAT C:\My Downloads\gmer.exe[1952] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetMessageW] 0013B777
IAT C:\My Downloads\gmer.exe[1952] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!PeekMessageA] 0013B7A3
IAT C:\My Downloads\gmer.exe[1952] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!PeekMessageW] 0013B7D2
---- Devices - GMER 1.0.13 ----
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE [F79620B7] xpdx.sys
Here is the other file:
GMER 1.0.13.12551 -
http://www.gmer.net
Autostart scan 2007-09-05 09:44:44
Windows 5.1.2600 Service Pack 2
HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems@Windows = %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon@Userinit = C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ntos.exe,
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ >>>
awvtu@DLLName = C:\WINDOWS\system32\awvtu.dll
efcbxxx@DLLName = efcbxxx.dll /*file not found*/
PCANotify@DLLName = PCANotify.dll
WgaLogon@DLLName = WgaLogon.dll
HKLM\SYSTEM\CurrentControlSet\Services\ >>>
aawservice /*Ad-Aware 2007 Service*/@ = "C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe"
Automatic LiveUpdate Scheduler /*Automatic LiveUpdate Scheduler*/@ = "C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe"
AVG Anti-Spyware Guard /*AVG Anti-Spyware Guard*/@ = C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
Crypkey License /*Crypkey License*/@ = crypserv.exe
MSSQL$ACT7 /*MSSQL$ACT7*/@ = C:\Program Files\Microsoft SQL Server\MSSQL$ACT7\Binn\sqlservr.exe -sACT7 /*file not found*/
RemoteRegistryxmlprov /*Remote Registry RemoteRegistryxmlprov*/@ = C:\WINDOWS\system32\adsldpr.exe srv
ScsiAccess /*ScsiAccess*/@ = C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe /*file not found*/
ScsiPort@ = %SystemRoot%\system32\drivers\scsiport.sys
Spooler /*Print Spooler*/@ = %SystemRoot%\system32\spoolsv.exe
SSDPSRVRSVP /*SSDP Discovery Service SSDPSRVRSVP*/@ = C:\WINDOWS\system32\advpack.dllz.exe srv
wfxsvc /*WinFax PRO*/@ = C:\WINDOWS\System32\WFXSVC.EXE
wuauservCryptSvc /*Automatic Updates wuauservCryptSvc*/@ = C:\WINDOWS\system32\acluib.exe srv
xmlprovSupportAnyPC /*Network Provisioning Service xmlprovSupportAnyPC*/@ = C:\WINDOWS\system32\adsndsr.exe srv
HKLM\Software\Microsoft\Windows\CurrentVersion\Run >>>
@WFXSwtchC:\PROGRA~1\WinFax\WFXSWTCH.exe = C:\PROGRA~1\WinFax\WFXSWTCH.exe
@WinFaxAppPortStarterwfxsnt40.exe = wfxsnt40.exe
@NeroCheckC:\WINDOWS\system32\NeroCheck.exe = C:\WINDOWS\system32\NeroCheck.exe
@StatusClient 2.6C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe /auto /*file not found*/ = C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe /auto /*file not found*/
@TomcatStartup 2.5C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp.exe = C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp.exe
@Acrobat Assistant 7.0"C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" = "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
@VT100 EmulatorC:\WINDOWS\system32\VT100.EXE = C:\WINDOWS\system32\VT100.EXE
@Windows FrameworkC:\DOCUME~1\Adams\LOCALS~1\Temp\frmwrk.exe = C:\DOCUME~1\Adams\LOCALS~1\Temp\frmwrk.exe
@salybyC:\Program Files\MSN Gaming Zone\salyby22011.exe = C:\Program Files\MSN Gaming Zone\salyby22011.exe
@SystemOptimizerrundll32.exe "C:\WINDOWS\system32\rjdlrfof.dll",forkonce = rundll32.exe "C:\WINDOWS\system32\rjdlrfof.dll",forkonce
@KernelFaultCheck%systemroot%\system32\dumprep 0 -k = %systemroot%\system32\dumprep 0 -k
HKCU\Software\Microsoft\Windows\CurrentVersion\Run >>>
@MSMSGS"C:\Program Files\Messenger\msmsgs.exe" /background = "C:\Program Files\Messenger\msmsgs.exe" /background
@ctfmon.exeC:\WINDOWS\system32\ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
@userinitC:\WINDOWS\system32\ntos.exe = C:\WINDOWS\system32\ntos.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad@UPnPMonitor = C:\WINDOWS\system32\upnpui.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks >>>
@{A213B520-C6C2-11d0-AF9D-008029E1027E}C:\Program Files\WinFax\WfxSeh32.Dll = C:\Program Files\WinFax\WfxSeh32.Dll
@{57B86673-276A-48B2-BAE7-C6DBB3020EB8}C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll = C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll
@{F4002052-AB29-4B33-8C8D-0E99084564EC}C:\WINDOWS\system32\efcbxxx.dll /*file not found*/ = C:\WINDOWS\system32\efcbxxx.dll /*file not found*/
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved >>>
@{42071714-76d4-11d1-8b24-00a0c9068ff3} /*Display Panning CPL Extension*/deskpan.dll /*file not found*/ = deskpan.dll /*file not found*/
@{30D02401-6A81-11d0-8274-00C04FD5AE38} /*IE Search Band*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{32683183-48a0-441b-a342-7c2a440a9478} /*Media Band*/(null) =
@{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} /*Shell DocObject Viewer*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{FBF23B40-E3F0-101B-8488-00AA003E56F8} /*InternetShortcut*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{3C374A40-BAE4-11CF-BF7D-00AA006946EE} /*Microsoft Url History Service*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{FF393560-C2A7-11CF-BFF4-444553540000} /*History*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{7BD29E00-76C1-11CF-9DD0-00A0C9034933} /*Temporary Internet Files*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{7BD29E01-76C1-11CF-9DD0-00A0C9034933} /*Temporary Internet Files*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{CFBFAE00-17A6-11D0-99CB-00C04FD64497} /*Microsoft Url Search Hook*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{3DC7A020-0ACD-11CF-A9BB-00AA004AE837} /*The Internet*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{871C5380-42A0-1069-A2EA-08002B30309D} /*Internet Name Space*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{BDEADF00-C265-11D0-BCED-00A0C90AB50F} /*Web Folders*/C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL = C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
@{0006F045-0000-0000-C000-000000000046} /*Microsoft Outlook Custom Icon Handler*/C:\Program Files\Microsoft Office\Office10\OLKFSTUB.DLL = C:\Program Files\Microsoft Office\Office10\OLKFSTUB.DLL
@{42042206-2D85-11D3-8CFF-005004838597} /*Microsoft Office HTML Icon Handler*/C:\Program Files\Microsoft Office\OFFICE11\msohev.dll = C:\Program Files\Microsoft Office\OFFICE11\msohev.dll
@{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} /*Shell Extensions for RealOne Player*/C:\Program Files\Real\RealPlayer\rpshell.dll = C:\Program Files\Real\RealPlayer\rpshell.dll
@{BB7DF450-F119-11CD-8465-00AA00425D90} /*Microsoft Access Custom Icon Handler*/C:\Program Files\Microsoft Office\Office\soa800.dll = C:\Program Files\Microsoft Office\Office\soa800.dll
@{596AB062-B4D2-4215-9F74-E9109B0A8153} /*Previous Versions Property Page*/C:\WINDOWS\System32\twext.dll = C:\WINDOWS\System32\twext.dll
@{9DB7A13C-F208-4981-8353-73CC61AE2783} /*Previous Versions*/C:\WINDOWS\System32\twext.dll = C:\WINDOWS\System32\twext.dll
@{692F0339-CBAA-47e6-B5B5-3B84DB604E87} /*Extensions Manager Folder*/C:\WINDOWS\system32\extmgr.dll = C:\WINDOWS\system32\extmgr.dll
@{B41DB860-8EE4-11D2-9906-E49FADC173CA} /*WinRAR shell extension*/C:\Program Files\WinRAR\rarext.dll = C:\Program Files\WinRAR\rarext.dll
@{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} /*Adobe.Acrobat.ContextMenu*/C:\Program Files\Adobe\Acrobat 7.0\Acrobat Elements\ContextMenu.dll = C:\Program Files\Adobe\Acrobat 7.0\Acrobat Elements\ContextMenu.dll
@{e57ce731-33e8-4c51-8354-bb4de9d215d1} /*Universal Plug and Play Devices*/C:\WINDOWS\system32\upnpui.dll = C:\WINDOWS\system32\upnpui.dll
@{07C45BB1-4A8C-4642-A1F5-237E7215FF66} /*IE Microsoft BrowserBand*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{1C1EDB47-CE22-4bbb-B608-77B48F83C823} /*IE Fade Task*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{205D7A97-F16D-4691-86EF-F3075DCCA57D} /*IE Menu Desk Bar*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{3028902F-6374-48b2-8DC6-9725E775B926} /*IE AutoComplete*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{43886CD5-6529-41c4-A707-7B3C92C05E68} /*IE Navigation Bar*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{44C76ECD-F7FA-411c-9929-1B77BA77F524} /*IE Menu Site*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{4B78D326-D922-44f9-AF2A-07805C2A3560} /*IE Menu Band*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{6038EF75-ABFC-4e59-AB6F-12D397F6568D} /*IE Microsoft History AutoComplete List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{6B4ECC4F-16D1-4474-94AB-5A763F2A54AE} /*IE Tracking Shell Menu*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{6CF48EF8-44CD-45d2-8832-A16EA016311B} /*IE IShellFolderBand*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{73CFD649-CD48-4fd8-A272-2070EA56526B} /*IE BandProxy*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{98FF6D4B-6387-4b0a-8FBD-C5C4BB17B4F8} /*IE MRU AutoComplete List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{9A096BB5-9DC3-4D1C-8526-C3CBF991EA4E} /*IE RSS Feeder Folder*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{9D958C62-3954-4b44-8FAB-C4670C1DB4C2} /*IE Microsoft Shell Folder AutoComplete List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{B31C5FAE-961F-415b-BAF0-E697A5178B94} /*IE Microsoft Multiple AutoComplete List Container*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{BC476F4C-D9D7-4100-8D4E-E043F6DEC409} /*Microsoft Browser Architecture*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{BFAD62EE-9D54-4b2a-BF3B-76F90697BD2A} /*IE Shell Rebar BandSite*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{E6EE9AAC-F76B-4947-8260-A9F136138E11} /*IE Shell Band Site Menu*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{F2CF5485-4E02-4f68-819C-B92DE9277049} /*&Links*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{F83DAC1C-9BB9-4f2b-B619-09819DA81B0E} /*IE Registry Tree Options Utility*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} /*IE User Assist*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{FDE7673D-2E19-4145-8376-BBD58C4BC7BA} /*IE Custom MRU AutoCompleted List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} /*Microsoft Office Metadata Handler*/C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll = C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
@{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} /*Microsoft Office Thumbnail Handler*/C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll = C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
@{2C49B5D0-ACE7-4D17-9DF0-A254A6C5A0C5} /*dBpoweramp Music Converter*/C:\Program Files\Illustrate\dBpoweramp\dMCShell.dll = C:\Program Files\Illustrate\dBpoweramp\dMCShell.dll
@{00E7B358-F65B-4dcf-83DF-CD026B94BFD4} /*Autoplay for SlideShow*/(null) =
HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved@{BDEADF00-C265-11d0-BCED-00A0C90AB50F} /*Web Folders*/ = C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ >>>
Adobe.Acrobat.ContextMenu@{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} = C:\Program Files\Adobe\Acrobat 7.0\Acrobat Elements\ContextMenu.dll
AVG Anti-Spyware@{8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll
MagicISO@{DB85C504-C730-49DD-BEC1-7B39C6103B7A} = C:\Program Files\MagicISO\misosh.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll
HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ >>>
AVG Anti-Spyware@{8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll
MagicISO@{DB85C504-C730-49DD-BEC1-7B39C6103B7A} = C:\Program Files\MagicISO\misosh.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll
HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ >>>
FineReader@{AC0DD14A-8F29-4F88-BE1D-0F0ED1B06C9F} = c:\program files\abbyy finereader 7.0 professional edition\fecmenu.dll
MagicISO@{DB85C504-C730-49DD-BEC1-7B39C6103B7A} = C:\Program Files\MagicISO\misosh.dll
MP3ToWave@{DC6FA7E0-6666-11D5-8CE2-444553540000} =
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects >>>
@{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll = C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
@{108F534D-DF89-453b-83E3-B12EBD5F0191}cupid1.dll = cupid1.dll
@{36cd15f1-07b3-4b16-b115-cf7203ea4703}C:\WINDOWS\system32\ljbtxyn.dll = C:\WINDOWS\system32\ljbtxyn.dll
@{56B60839-C8B2-4543-B818-9977CF946511}C:\WINDOWS\system32\awvtu.dll = C:\WINDOWS\system32\awvtu.dll
@{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll = C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
@{AE7CD045-E861-484f-8273-0445EE161910}C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll = C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
@{CF46BFB3-2ACC-441b-B82B-36B9562C7FF1}C:\WINDOWS\system32\wbwrycth.dll = C:\WINDOWS\system32\wbwrycth.dll
@{F096F83E-CF5B-4A18-1C8F-10707D3E8B65}C:\Program Files\Messenger\wopu.dll = C:\Program Files\Messenger\wopu.dll
@{F4002052-AB29-4B33-8C8D-0E99084564EC}C:\WINDOWS\system32\efcbxxx.dll /*file not found*/ = C:\WINDOWS\system32\efcbxxx.dll /*file not found*/
HKCU\Control Panel\Desktop@SCRNSAVE.EXE = C:\WINDOWS\System32\ssstars.scr
HKLM\Software\Microsoft\Internet Explorer\Main >>>
@Default_Page_URLhttp://go.microsoft.com/fwlink/?LinkId=69157 =
http://go.microsoft....k/?LinkId=69157
@Start Pagehttp://go.microsoft.com/fwlink/?LinkId=69157 =
http://go.microsoft....k/?LinkId=69157
@Local Page%SystemRoot%\system32\blank.htm = %SystemRoot%\system32\blank.htm
HKCU\Software\Microsoft\Internet Explorer\Main >>>
@Start Pagehttp://www.msn.com/ =
http://www.msn.com/
@Local PageC:\WINDOWS\system32\blank.htm = C:\WINDOWS\system32\blank.htm
HKLM\Software\Classes\PROTOCOLS\Filter\text/xml@CLSID = C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
HKLM\Software\Classes\PROTOCOLS\Handler\ >>>
cdo@CLSID = C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL
dvd@CLSID = C:\WINDOWS\system32\msvidctl.dll
its@CLSID = C:\WINDOWS\System32\itss.dll
lid@CLSID = C:\WINDOWS\System32\msvidctl.dll
mhtml@CLSID = /*file not found*/
ms-its@CLSID = C:\WINDOWS\System32\itss.dll
ms-itss@CLSID = C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll
msnim@CLSID = "C:\PROGRA~1\MSNMES~1\msgrapp.dll"
mso-offdap@CLSID = C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
mso-offdap11@CLSID = C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
tv@CLSID = C:\WINDOWS\system32\msvidctl.dll
wia@CLSID = C:\WINDOWS\System32\wiascr.dll
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{80D48597-AE2A-4D1B-BA99-217A3EC5C0B9} /*Local Area Connection*/ >>>
@IPAddress192.168.0.136 = 192.168.0.136
@NameServer10.0.0.2 = 10.0.0.2
@DefaultGateway192.168.0.1 = 192.168.0.1
@Domain =
C:\Documents and Settings\All Users\Start Menu\Programs\Startup >>>
Adobe Acrobat Speed Launcher.lnk = Adobe Acrobat Speed Launcher.lnk
Adobe Gamma Loader.lnk = Adobe Gamma Loader.lnk
Microsoft Office.lnk = Microsoft Office.lnk
QuickBooks 2002 Delivery Agent.lnk = QuickBooks 2002 Delivery Agent.lnk
---- EOF - GMER 1.0.13 ----